Streamline Amazon Workspaces Management with Intune Implementation Guide
Total Page:16
File Type:pdf, Size:1020Kb
Streamline Amazon WorkSpaces Management with Intune Implementation Guide June 10, 2021 Notices Customers are responsible for making their own independent assessment of the information in this document. This document: (a) is for informational purposes only, (b) represents current AWS product offerings and practices, which are subject to change without notice, and (c) does not create any commitments or assurances from AWS and its affiliates, suppliers or licensors. AWS products or services are provided “as is” without warranties, representations, or conditions of any kind, whether express or implied. The responsibilities and liabilities of AWS to its customers are controlled by AWS agreements, and this document is not part of, nor does it modify, any agreement between AWS and its customers. © 2021 Amazon Web Services, Inc. or its affiliates. All rights reserved. Contents Overview .............................................................................................................................. 1 Cost ...................................................................................................................................... 1 Services Used and Costs ................................................................................................. 2 Architecture overview .......................................................................................................... 4 Walkthrough ......................................................................................................................... 5 Prerequisites..................................................................................................................... 5 Step 1: Establish Azure Active Directory Hybrid Environment for Amazon WorkSpaces .......................................................................................................................................... 7 Step 2: Configure Group Policy to Hybrid-join Azure Active Directory ......................... 15 Step 3: Assign Azure Intune Licensing to Amazon WorkSpaces User Group ............. 17 Step 4: Configure Intune Windows Enrollment for Amazon WorkSpaces ................... 19 Step 5: Authenticate to Amazon WorkSpaces Client using Windows AD UPN ........... 24 Step 6: Confirm Amazon WorkSpaces Intune Enrollment ............................................ 25 Step 7: Clean Up ............................................................................................................ 27 Conclusion ......................................................................................................................... 27 Contributors ....................................................................................................................... 27 Additional resources .......................................................................................................... 28 Document Revisions.......................................................................................................... 28 About this Guide This guide walks you through the process of setting up Windows Intune and Amazon WorkSpaces using Hybrid Azure Active Directory Join. Specifically, you learn how to establish an Azure Active Directory environment for hybrid join and configure Microsoft Intune for Amazon WorkSpaces to allow user credential-based enrollment, extending your existing Intune Windows 10 management to Amazon WorkSpaces beyond organizational desktops and laptops. This guide requires Bring Your Own License (BYOL) for Windows 10 Amazon WorkSpaces. License-included Amazon WorkSpaces is not supported with this implementation guide. Amazon Web Services Streamline Amazon WorkSpaces Management with Intune Overview Amazon WorkSpaces are secure, persistent virtual desktops in the AWS Cloud. These virtual desktops are normally joined to a customer’s existing domain, allowing them to work seamlessly with existing tools and corporate resources. Customers can leverage the time and effort put into the development and customization of these tools by extending them into their Amazon WorkSpaces environment. This provides flexibility for IT administrators and accelerates adoption for end-users as a customer goes through their End User Compute journey on AWS. This guide walks through the process of integrating Microsoft Autopilot with an existing Bring Your Own License (BYOL) Amazon WorkSpaces deployment. Each WorkSpaces instance is assigned to a single user whose applications, documents, and settings persist throughout the lifecycle of the instance, much like existing end-user devices. Just like end-user devices, WorkSpaces instances require ongoing operating system (OS) maintenance and application updates throughout their lifecycle to stay current. Customers can use Windows Autopilot to manage existing WorkSpaces and automate the onboarding process of a WorkSpaces instance to end- users, without IT Admin involvement. Consider the following scenario that benefits from using Windows Intune with Amazon WorkSpaces: Streamline onboarding remote corporate users: This scenario allows users to onboard from home and access their corporate environment resources to be productive from Day 1. IT administrators create and apply configuration profiles to provisioned WorkSpaces instances, while end-users initiate the onboarding process when they log into their instance for the first time. After login, the OS and applications are fully patched, and the instance is completely compliant without IT administrator involvement. This workflow can all be accomplished without coming into an office. Cost The total cost for setting up Windows Autopilot with Amazon WorkSpaces varies depending on several factors, including the following: • Amazon Elastic Compute Cloud (Amazon EC2) instance size based on number Active Directory (AD) objects already in use and in the possible future o Less than 100,000 objects = m5.large with 100GB GP3 Volume 1 Amazon Web Services Streamline Amazon WorkSpaces Management with Intune o More than 100,000 objects = m5.2xlarge with 500GB GP3 Volume + Microsoft SQL Server This implementation uses a Microsoft trial license called Enterprise Mobility + Security E5 and an Amazon EC2 m5.large instance with 100 GB of Amazon EBS storage. It costs approximately $8.76 to complete the walkthrough if you use the default configuration recommended in this guide. This estimate assumes that the infrastructure you create during the walkthrough is running for 4 hours. The cost estimate is based on pricing for US East N. Virginia. A breakdown of the services used and their associated costs is provided in the following section. Services Used and Costs AWS pricing is based on your usage of each individual service. The total combined usage of each service creates your monthly bill. For this tutorial, you are charged for the use of Amazon WorkSpaces, a custom domain name, and an Amazon EC2 instance. Amazon WorkSpaces Description: Amazon WorkSpaces is a fully managed, secure desktop computing service which runs on the AWS Cloud. Amazon WorkSpaces allows you to easily provision cloud-based virtual desktops and provide your users access to the documents, applications, and resources they need from any supported device, including Windows, Linux, and Mac computers, Chromebooks, iPads, Kindle Fire tablets, and Android tablets. How Pricing Works: With Amazon WorkSpaces, you pay only for the Amazon WorkSpaces you launch. There is no up-front commitment and you can delete Amazon WorkSpaces at any time. Amazon WorkSpaces provides the flexibility to pay monthly or hourly. With monthly billing, you pay a fixed monthly fee for unlimited usage during the month. With hourly billing you pay a small fixed monthly fee per Amazon WorkSpace to cover infrastructure costs and storage, and a low hourly rate for each hour the Amazon WorkSpace is used during the month. There are different bundles to choose from – Value, Standard, Performance, Power, PowerPro, Graphics and GraphicsPro. Pricing includes compute, storage, software, and bandwidth between your Amazon WorkSpace and your Amazon WorkSpaces client application. Accessing the public Internet from your Amazon WorkSpace is charged 2 Amazon Web Services Streamline Amazon WorkSpaces Management with Intune separately at current rates, published in “Data Transfer OUT”. See the Amazon WorkSpaces pricing page for more information. Example: In this project, you create one Amazon WorkSpace, using the Bring Your Own License (BYOL) Performance bundle, paying hourly or monthly. In the US East (N. Virginia) Region, the hourly price for the Performance bundle is $0.43 plus a $7.25 monthly fee. Assuming that your Amazon WorkSpace run for a total of 4 hours during this project, the total cost would be $8.97. Should you choose to pay monthly instead, your total cost would be $41. Note: The monthly fee for Amazon WorkSpaces is prorated for the remainder of the first month of usage. The price listed is based on the Root and User Volume 80/10 option. Amazon Route 53 Description: Amazon Route 53 is a highly available and scalable cloud Domain Name System (DNS) web service. It is designed to give developers and businesses an extremely reliable and cost-effective way to route end users to Internet applications by translating names like www.example.com into the numeric IP addresses like 192.0.2.1 that computers use to connect to each other. Amazon Route 53 is fully compliant with IPv6 as well. How Pricing Works: With Amazon Route 53, you don’t have to pay any upfront fees or commit to the number